Live data from Hacker News

1B identity records exposed in ID verification data leak

aol.com

41–50 of 67 posts

Re: 1B identity records exposed in ID verification data leak

#41
post #6

Almost a month old, original source: https://cybernews.com/security/global-data-leak-exposes-bill... and I've never seen any confirmation elsewhere Looks like CyberNews have edited the article with more info since first I saw it, it used to look quite suspicious and untrustworthy, it now has more info. Still doesn't say exactly what a record is, or how many uniques there are.

To sum up the updates in the article

  - IDMerit asked the security researcher for proof, the researcher asked for money first, so IDMerit balked
  - IDMerit basically says they have no proof they were hacked, so they weren't
  - The researcher is a freelancer... for CyberNews...
Even if somebody followed up with IDMerit, it's likely they will say they are not affected. The security researcher is probably the only person who could prove whether they were or not vulnerable, at this point. If they don't come forward, we can only assume they weren't vulnerable, but we don't know. This is a good lesson for responsible disclosure in the future.

...also, this is yet another example of why we need a regulated Software Building Code, with penalties for not conforming to it. If somebody is found to be hosting a public Mongo instance with no authentication, it should be reported to a state or federal agency, so that real penalties can be applied, the way they are for other code violations. And they shouldn't have been allowed to launch with that in the first place. It shouldn't be up to random "security researchers" to police businesses.

Re: 1B identity records exposed in ID verification data leak

#43
This made me absolutely livid:

> We requested a security incident report from the ethical hackers as proof

So instead of paying him a fair bug bounty, they demand that he write a formal report for them and prove to them that there is even a problem.

Totally unhinged, but it gets worse:

> the response was a demand for money for the report, which confirmed our suspicion that this was a ransom-related incident.

Wow. So when the security researcher informs them that he would be happy to do some consulting work for them and informs them of his rates, they flip out and accuse his initial good samaritan decision to inform the company of the issue of being part of a plot by him to hold the company for ransom?

Whoever thought this is both totally delusional and a complete jerk. Truly, no good deed goes unpunished.

Re: 1B identity records exposed in ID verification data leak

#44
post #30

While this leak may or may not have happened, for this type of exposure there should be criminal liability for developers and executives. Criminal negligence and prison time.

If developers are going to face criminal liability, they should IMHO also have legal ways to push back against certain implementations without risking their jobs, or at least have a way to leave a legal justification somewhere: "I'm doing this because I'm forced to but I disagree" which is then signed by management. Until then, you're putting the weight of the law on the wrong side of the equation, since developers a…

Most countries already have whistleblower laws. If you are living somewhere that has any kind of "wrongful termination" legislation, an employer asking you to commit a crime is an open and shut case. I would guess that all of the USA and Europe would have existing sufficient protections, for example (although the US never ceases to surprise me).

Re: 1B identity records exposed in ID verification data leak

#45
> We own and operate our proprietary platform, but we do not own, control or store customer data or the underlying data maintained by independent data sources.

This seems like a critical sentence. Is this database actually operated by IDMerit, or someone else? If so, who?

Re: 1B identity records exposed in ID verification data leak

#46
post #30

While this leak may or may not have happened, for this type of exposure there should be criminal liability for developers and executives. Criminal negligence and prison time.

If developers are going to face criminal liability, they should IMHO also have legal ways to push back against certain implementations without risking their jobs, or at least have a way to leave a legal justification somewhere: "I'm doing this because I'm forced to but I disagree" which is then signed by management. Until then, you're putting the weight of the law on the wrong side of the equation, since developers a…

They won’t do it just for protection.

The state would need to offer an award, and maybe witness relocation

Re: 1B identity records exposed in ID verification data leak

#49
post #11

Earlier quoted context omitted.

GDPR doesn't apply in the states, but hopefully it provides for some punishment for the poor security here for EU customers. Of course, then some Americans will get mad that a US company has to follow EU law.

The GDPR applies worldwide to any data held about EU or UK citizens, regardless of where they reside. It does apply in the US, it's just potentially harder for the EU to enforce meaningful penalties for infractions.

> It does apply in the US

EU law does not apply to US citizens residing in the US with no ties to the EU.

Re: 1B identity records exposed in ID verification data leak

#50

Earlier quoted context omitted.

The GDPR applies worldwide to any data held about EU or UK citizens, regardless of where they reside. It does apply in the US, it's just potentially harder for the EU to enforce meaningful penalties for infractions.

> It does apply in the US EU law does not apply to US citizens residing in the US with no ties to the EU.

Correct. It does not apply to US citizens residing anywhere in the world. It does, however, as I said, apply to EU citizens regardless of where in the world they reside.

If a company holds data about EU citizens, the GDPR applies to them, regardless of where that company is based. Including the US. Hence the statement "It (GDPR) does apply in the US" is completely correct.

Post reply on HN